livepro[.]ghost[.]io
Перевірка домену livepro.ghost.io на фішинг і безпеку
“Ledger Live”
livepro.ghost.io — Останній відомий активний (HTTP 301). Уособлення бренду: Ledger; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 5/91 (ChainPatrol, alphaMountain.ai, Chong Lua Dao, Gridinsoft, Webroot); URLScan malicious verdict; PhishDestroy score 80/100. Реєстратор: 1API.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, livepro.ghost.io, is identified as a brand impersonation threat targeting Ledger, a hardware cryptocurrency wallet provider. The site mimics the official Ledger Live interface, a platform used for managing crypto assets, with the page title explicitly set to "Ledger Live." Such impersonation domains are commonly deployed to harvest credentials, private keys, or seed phrases, often leading to unauthorized asset transfers or crypto drainer attacks. No specific drainer kit signatures were confirmed in this instance, but the infrastructure aligns with known credential theft campaigns in the cryptocurrency sector. Analysis indicates the domain was flagged by 3 out of 95 security vendors on VirusTotal, suggesting moderate detection at the time of assessment. It was registered through 1API GmbH, a registrar frequently utilized in both legitimate and malicious operations. The domain resolves to the IP address 18.239.6.36, which has been associated with other low-reputation hosting environments. Created on October 01, 2011, the domain predates the recent surge in crypto-themed phishing but was likely repurposed for malicious use. It appears on one security blocklist, and no entries were found in Google Safe Browsing at the time of this report. The domain is currently offline, reducing immediate exposure risk to end users. However, the infrastructure remains registered and could be reactivated. Organizations and individuals are advised to monitor for renewed activity, particularly if the domain reappears under altered hosting or SSL configurations. Network defenders should update blocklists to include this domain and its associated IP address. Users who may have interacted with the site should revoke any connected wallet permissions and audit their accounts for unauthorized transactions. The elevated risk classification reflects the potential for financial loss if the domain resumes operation.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of livepro.ghost.io · checked Mar 2, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога